Back to the deskहिन्दी में पढ़ें

Guide

The 'Boss Scam': a hijacked WhatsApp orders an urgent payment. A call-back checklist for firms

Severity: HighPublished IndiaThreats2026-1003-VQ12 min readBy Vivek Kumar
Illustration of a phone showing a chat from 'Boss': 'In a meeting. Transfer ₹4.8 lakh now, urgent.' with a warning sign, beside a sticky note saying CALL TO VERIFY. Text: BOSS SCAM.

AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.

Fraudsters take over a senior executive's WhatsApp, or save their own number under the boss's name, and tell finance staff to pay at once. What I4C and SEBI say, and a call-back checklist for small firms and CA offices.

01 / The short answer

A WhatsApp message arrives from your boss, a partner or a director: pay this amount into this account, now. The name is right and the photo is right. The number may be right too. In what the Indian Cyber Crime Coordination Centre (I4C) says is commonly called the 'Boss Scam', fraudsters use a senior executive's genuine WhatsApp account after taking it over, or secretly save their own number under the boss's name on a compromised device. The money goes to mule accounts.

The right name on the screen does not mean the right person is typing.

The defence is a single habit, and both I4C and the market regulator SEBI describe it: before you act on a payment instruction that came by WhatsApp or email, check it by calling the person yourself. I4C adds that you can also confirm in person. Section 05 turns this into a checklist for whoever makes payments in your office. Already paid? Call 1930 now. Section 08 has the steps.

02 / How it works, according to I4C

I4C, which is part of the Home Ministry, described the campaign in a release on 7 August 2026. It said it had seen a sharp rise in complaints on the National Cyber Crime Reporting Portal about WhatsApp accounts of professionals and businesspersons being taken over, with incidents from several states, including Delhi, Gujarat, Maharashtra and Rajasthan. As I4C describes it:

  • The bait. A .zip file arrives on WhatsApp, by SMS or by email, with a name such as 'Statement of Account.zip' (often with a date in front, for example '0714 Statement of Account.zip'), 'RBI.zip' or 'MCA.zip'. The message looks like a routine account statement or an urgent notice from the RBI or the Ministry of Corporate Affairs, and demands action within a very short time. In many cases, I4C says, emails also impersonate the Income Tax Department.
  • The takeover. Inside is a Windows program (.exe) with a .dll file. Extracted and opened on a Windows desktop or laptop, it installs a Trojan that compromises the computer and hijacks the WhatsApp Web session that is open on it.
  • The spread. The hijacked account sends the same file to all the victim's contacts and groups, typically asking them to forward it to their 'company finance manager for verification' and to open it on a computer. I4C says this carries the infection deeper into corporate networks.
  • The payment order. In the advanced stage, which I4C says is commonly called the 'Boss Scam' or CEO impersonation fraud, fraudsters use a senior executive's genuine WhatsApp account, or covertly save a number they control under the name of the 'CEO' on the compromised device. Then they tell accounts and finance staff to make urgent transfers to mule bank accounts (how mule accounts work).

Because the malware works only on Windows computers, and the bait is about account statements and regulatory compliance, I4C says Chartered Accountants, company directors, CFOs and finance and accounts staff are at particular risk. Its threat analytics unit says its analysis indicates the campaign is run by organised networks operating across national borders. To check whether your own WhatsApp has an intruder, see our guide to hijacked WhatsApp accounts.

03 / Real cases, as reported

The cases below come from media reports that cite police or the complaint; we have not seen the FIRs, so treat every detail as Reported. In the two 2026 Mumbai cases, the reports describe a message from a new number carrying the director's name or photo; they do not mention a hijacked account or the .zip malware. The habit that would have stopped them is the same.

  • Mumbai, June 2026: ₹10.4 crore in 63 transfers. Business Today, citing police, reports that on 3 June an accounts employee of a Mumbai private firm got a WhatsApp message from an unknown number that used the executive director's photo. The sender asked to be saved as a 'personal contact', and said he was in an urgent meeting and could not take calls. Between 3 and 15 June the employee made 63 transfers totalling ₹10,40,71,924. It came to light only when the employee contacted the real executive director through official channels. Business Today reports that Delhi Police arrested four people, and that two of them admitted during questioning that they let their bank accounts be used to move the money for a commission. Aaj Tak says five were arrested and that the sender posed as the CEO. Those arrested are accused, not convicted.
  • Mumbai, August 2026: ₹1.98 crore, most of it frozen. The Free Press Journal, citing the FIR, reports that a Mumbai firm's general manager (accounts) got a WhatsApp message from a new number with the director's name and photo, saying 'this is my new contact number'. The next day the same number asked for an urgent client payment of ₹1.98 crore, and he made it. The fraud came to light when he and the real director spoke by phone. A complaint was made on 1930 and an FIR was registered. UNI and, in a second report, the Free Press Journal say police then froze and recovered ₹1.83 crore, about 92% of the amount. The reports give different dates for the messages, so we do not print them.
  • An older case: Serum Institute of India, Pune, September 2022. The Quint, with inputs from PTI, reported on 12 September 2022 that fraudsters posing on WhatsApp as the company's CEO, Adar Poonawalla, asked the director of its finance department to transfer money at once to certain bank accounts. The company transferred ₹1,01,01,554. Police registered an FIR for cheating and offences under the Information Technology Act.

Two lessons stand out. A 'boss' who cannot take calls is a reason to wait, not to pay (section 05). And reporting fast matters: in the second case, police say the 1930 helpline and the cyber police station froze most of the money after the complainant reported it immediately.

04 / What SEBI adds: deepfakes, Teams and 'keep it quiet'

Three weeks before the I4C release, on 17 July 2026, SEBI issued press release No. 40/2026 to regulated entities and listed companies. It says I4C had told SEBI about the trend, which SEBI calls the 'Boss Scam' or CEO/MD impersonation fraud. SEBI's account is wider in two ways.

  • Not only WhatsApp. SEBI says the instructions reach subordinates or counterparts by email, WhatsApp, Microsoft Teams or other social media platforms.
  • Not only malware. Besides the .zip route, SEBI describes impersonation of MDs and CEOs through deepfakes: voice cloning, AI used on video calls, and fake groups on social media posing as senior officials. In our view, that means a call or video call in the boss's voice or face, which you did not place yourself, is not proof on its own (how voice-clone calls work).

SEBI also notes a detail finance staff should know. In the deepfake route, the order to pay into a mule account may come with a direction not to share the transaction, because it may be 'Unpublished Price Sensitive Information'. In a listed company that can sound like a genuine compliance reason. We would treat it as a warning sign: secrecy is what stops the call that would expose the fraud.

On the malware route, SEBI, citing I4C, says the CEO forwards the .zip message to finance officers. When a finance officer opens it on a Windows computer, the attacker gets into that officer's WhatsApp and uses it to tell accounts staff to make immediate payments. If they take over the device completely, SEBI says, fraudsters can secretly change its contact list so that their own number appears under the CEO's or MD's name.

05 / The call-back checklist for staff who handle payments

I4C advises companies to sensitise their staff, finance teams above all, and to verify any urgent fund-transfer instruction or account-change request received over WhatsApp or email independently, by a direct voice call or in person, before acting on it. SEBI says not to transfer funds solely on instructions received on social media platforms. The checklist below turns that advice into a routine. Where a point comes from I4C or SEBI, we say so; the rest are our suggestions.

  1. No payment on a message alone. A WhatsApp text, email, Teams message, voice note or forwarded screenshot is a request, not an approval. SEBI's advice is not to transfer funds solely on instructions received on social media platforms, and I4C's is to verify instructions received over WhatsApp or email before acting on them.
  2. Call out, on a number you already had. Use the number in your staff list, contract or supplier records, saved before this request arrived. Do not use a number given in the message, and do not simply tap the name in WhatsApp: I4C and SEBI both say fraudsters can save their own number under the boss's name. We suggest a normal phone call, not a call or reply inside the same chat.
  3. A call you receive is not a call-back. SEBI warns of voice cloning and AI video calls posing as MDs and CEOs. If 'the boss' rings you to push the payment, hang up and call back on the number you have.
  4. No answer, no payment. If you cannot reach the person, or they say they cannot talk and you must pay anyway, wait. A delay of an hour costs far less than a transfer you may not get back.
  5. 'Keep it confidential' is a reason to check, not to skip. SEBI says fraudsters may tell finance staff not to share the transaction as it may be price-sensitive. A confidential payment can still go through your normal approvals.
  6. New account or changed bank details? Check with the payee too. I4C lists account-change requests alongside payment orders. Call the supplier or client on the number already in your records before paying into an account you have not paid before. You can practise on a fictional example in our Scam Lab: a supplier's invoice with changed bank details.
  7. Two people for a new payee. One person sets up the payment and another approves it after the call-back, so the person who received the message is not the only check.
  8. Write it down. Note who you called, on which number, at what time, and what they said. It takes a minute, and it makes a skipped check easy to spot.

06 / For owners, partners and CA offices: close the door the malware uses

  • Do not open .zip files or programs that arrive on WhatsApp until you have checked with the sender by a call, even if the sender is someone you know. I4C says not to download, extract or open .zip files or executables from unknown or unverified sources, and that regulators such as the RBI never send software updates, security fixes or account statements as WhatsApp attachments. SEBI says not to install executables without verifying who sent them, and to verify by a call if they come from someone you know.
  • Go to the source for notices. If a message says a notice from the RBI, the MCA or the Income Tax Department is attached, our advice is to check on that body's own website or portal, opened by typing the address yourself, rather than opening the file.
  • Log out of WhatsApp Web where you are not using it. I4C and SEBI both advise logging out of WhatsApp Web sessions that are not in active use, and I4C says to review Settings > Linked Devices regularly. In an office, a partner's WhatsApp left logged in on a shared computer is exposed to whatever anyone else opens on that computer.
  • Lock down Windows computers. I4C advises system administrators to use software restriction policies to stop unknown .exe and .dll files from running from user profile folders, and to keep up-to-date anti-malware on every Windows computer. If you have no IT staff, ask whoever looks after your computers to set this up.
  • Tell your staff and your clients. I4C asks companies to sensitise employees at once, especially finance teams. A CA office can also tell its clients how it does and does not send documents and payment requests, so that a .zip file 'from you' looks wrong to them.
  • Do not ignore an SMS from I4CMHA-G. I4C says it sends alerts to affected citizens from this SMS header, and asks people to act promptly on the advice in them. It alerted more than 58,000 potential victims this way in the 30 days before its 7 August release. The release does not give the wording of the alerts, so check that the sender really is I4CMHA-G, and act by opening WhatsApp yourself, not through a link.

07 / What we confirmed, and what we could not

Confirmed (official sources): how the .zip campaign and the 'Boss Scam' stage work, the states named, the groups at particular risk, I4C's advice, and its figures of more than 58,000 potential victims alerted and more than 10,000 people protected so far (PIB, I4C release of 7 August 2026); the deepfake route, Microsoft Teams, the 'price-sensitive' secrecy direction and SEBI's advice (SEBI PR No. 40/2026, 17 July 2026). Reported (media): The Tribune (7 August 2026) and Business Today (25 August 2026) reported I4C's warning; on this campaign, neither adds facts beyond the release. The three cases in section 03 are reported by Business Today and Aaj Tak (June 2026), the Free Press Journal and UNI (August 2026) and The Quint/PTI (September 2022). The reports differ on how many people were arrested in the June case (four or five) and whether the sender posed as the executive director or the CEO, and on the dates of the messages in the August case. Claimed (by the fraudsters' messages): that a statement or a regulator's notice is attached, that the boss needs money moved at once, and that the payment must be kept secret. Not available: I4C's advisory of 22 June 2026, titled 'Regulatory and Executive Impersonation for WhatsApp Account Takeover using Malicious Windows Executables and High Value Financial Fraud', which the release says is on cybercrime.gov.in but which was not in the portal's advisories list when we checked on 3 October 2026; any official count of complaints or of money lost; the names of affected firms. The points in sections 05 and 06 that are not attributed to I4C or SEBI are our own advice.

08 / Already paid, or an account hijacked? What to do now

  • Money has gone: call 1930 now, then your bank on its official number, then complete the complaint on cybercrime.gov.in. I4C and SEBI both point to 1930 and cybercrime.gov.in. Our lost-money checklist covers the first hour.
  • A WhatsApp account in your office has been hijacked: I4C says to log out of all linked devices at once, tell contacts not to open any file received from the account, and get the computer scanned with an updated antivirus. Our guide to hijacked WhatsApp accounts has the full recovery steps. To be safe, we suggest also treating passwords used on that computer as exposed: get it cleaned, then change them from another device (what to do after a malware infection).
  • You got the .zip or the payment order and did not fall for it: call the person it seems to come from, on the number you already have, because their account may be in someone else's hands. Then report it on cybercrime.gov.in, as I4C advises for suspicious messages of this kind (how to report).
  • Ignore anyone who offers to get the money back for a fee: what recovery really looks like.

Source log / 2026-1003-VQ

More from the archive